ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise
ASEC June 2026 APT Trend Report (TL-2026-1287), also tracked as ASEC June 2026 APT Trend Report, is a medium-severity campaign, first published 2026-07-14. It is attributed to APT38 (North Korea, China, Russia, Iran) with high confidence, affects Microsoft Microsoft Office, references 1 CVE (CVE-2026-21509), maps to 30 MITRE ATT&CK techniques (T1005, T1014, T1016), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-1287
- Threat ID
- TL-2026-1287
- Also known as
- ASEC June 2026 APT Trend Report, APT Group Threat Report - June 2026
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- CAMPAIGN
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea, China, Russia, Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomacy, defense, medical-research, energy, finance, telecom, transport, software-development, retail-investors
- Target regions
- ukraine, india, pakistan, china, south korea, vietnam, cambodia, israel, Middle East, united states of america, Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in ASEC June 2026 APT Trend Report
Malware and tooling: ChainShell, INFINITERED, NIGHTFORGE, NarwhalRAT, NightshadeC2 (Windows), PixyNetLoader, SHARDLOADER, SPECTRALVIPER, STOCKSTAY, SprySOCKS, X-Agent, XTunnel
AhnLab ASEC's June 2026 APT trend digest tracks 20 nation-state groups (North Korea, China, Russia, Iran, India/Southeast Asia) converging on a shared modern playbook: OAuth token theft, abuse of legitimate cloud services (Google Drive, Dropbox, pCloud, Zoho WorkDrive, FILEN) for C2/delivery, npm and vendor-update supply-chain compromise, and adoption of criminal malware-as-a-service platforms such as CastleRAT.
How ASEC June 2026 APT Trend Report works
AhnLab Security Emergency response Center (ASEC) published a monthly APT trend report on 2026-07-14 covering June 2026 activity from 20 tracked nation-state groups. The report is a digest-level roundup rather than a single-incident advisory: it names threat actors, malware families, and TTP categories per region without providing raw IOCs, CVEs, or CVSS scores for the digest itself. Follow-on research against the individually cited campaigns (independently reported by Microsoft, Google/Mandiant, ESET, ThreatLabz/Zscaler, Trellix, and CISA) supplies the technical depth: North Korea's Sapphire Sleet compromised the @mastra npm organization on 2026-06-17, backdooring 140+ packages (combined 1.1M+ weekly downloads) via a typosquatted 'easy-day-js' dependency with an obfuscated postinstall dropper; APT37/ScarCruft deployed the Python-loader-based NarwhalRAT via fake Microsoft security-alert phishing; China-nexus FishMonger (tracked historically as Earth Lusca/Aquatic Panda/Bronze University/Charcoal Typhoon/RedHotel) ported the Linux SprySOCKS backdoor to Windows with a kernel-driver rootkit and UEFI bootkit indicators, while other China-nexus clusters (UNC6508 et al.) abused Zoho WorkDrive as C2 infrastructure and OAuth tokens for persistent access to victim government, diplomatic, medical-research, and energy-sector environments; Russia's APT28 (Fancy Bear) ran Operation Neusploit exploiting CVE-2026-21509 in Microsoft Office to deliver PixyNetLoader, which hides shellcode in PNG images via LSB steganography and achieves persistence through COM object hijacking, while Turla (Secret Blizzard) deployed the KAZUAR-derived .NET/WebSocket backdoor STOCKSTAY against Ukrainian government/military and Italian-diplomacy-themed targets; Iran's MuddyWater (tied to Iran's MOIS) was found operating at least two builds of the Russian-developed CastleRAT malware-as-a-service platform alongside a new JavaScript/Node.js implant, ChainShell, that resolves its C2 address from an Ethereum smart contract and communicates over AES-encrypted WebSockets, discovered via an open C2 directory listing containing Farsi comments and Israeli IP-range target lists (Ctrl-Alt-Intel, 2026-03-04); and Vietnam-aligned OceanLotus (APT32) ran a supply-chain compromise of the FireAnt MetaKit stock-investment platform's update server (Oct 2025-Mar 2026) to selectively deliver the SPECTRALVIPER backdoor to Vietnamese stock investors. Collectively the report documents a strategic shift away from bespoke malware-only operations toward abuse of legitimate developer and cloud infrastructure, criminal MaaS procurement, and supply-chain trust exploitation across all tracked regions.
MITRE ATT&CK techniques used in TL-2026-1287
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1014 Rootkit; T1027.003 Steganography; T1140 Deobfuscate/Decode Files or Information; T1542.003 Bootkit
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography
Initial Access
T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
initial-access
T1195.002 Compromise Software Supply Chain
Persistence
T1505 Server Software Component; T1546.015 Component Object Model Hijacking
Credential Access
T1528 Steal Application Access Token; T1555.003 Credentials from Web Browsers
Exfiltration
T1567.002 Exfiltration to Cloud Storage
stealth
Resource Development
T1583.006 Web Services; T1588.001 Malware; T1608 Stage Capabilities
Affected products and versions in ASEC June 2026 APT Trend Report
- Microsoft — Microsoft Office
Vulnerable versions: versions affected by CVE-2026-21509
Fixed in: patched per Microsoft security update, see vendor advisory - Mastra AI / npm registry — @mastra npm package ecosystem (including @mastra/core) and easy-day-js dependency
Vulnerable versions: packages republished 2026-06-17 with easy-day-js@1.11.21+ dependency
Fixed in: packages republished after remediation removing easy-day-js dependency - FireAnt (Vietnam) — FireAnt MetaKit stock-investment platform update mechanism
Vulnerable versions: update server compromised Oct 2025-Mar 2026
Fixed in: update server remediated post-disclosure June 2026
Remediation for ASEC June 2026 APT Trend Report
Patches
- Apply Microsoft Office security update addressing CVE-2026-21509
Immediate actions
- Audit and revoke unused/overprivileged OAuth application tokens across Google Workspace, Microsoft 365, and other SSO-integrated SaaS
- Restrict or monitor outbound traffic to consumer cloud-storage domains (Google Drive, Dropbox, pCloud, Zoho WorkDrive, FILEN) from endpoints that should not need them for C2-shaped patterns
- Pin npm/package-manager dependencies with lockfiles and verify package provenance/signing before CI/CD install; block postinstall scripts in build pipelines where feasible
- Patch Microsoft Office against CVE-2026-21509 (Operation Neusploit / APT28)
Workarounds
- Block/quarantine easy-day-js and any Mastra package versions published between 2026-06-16 and 2026-06-19 pending provenance verification
- Disable macro/COM auto-execution and restrict COM object registration paths where PixyNetLoader-style hijacking is a concern
Longer-term hardening
- Deploy EDR with kernel-driver/rootkit detection and UEFI/firmware integrity attestation given SprySOCKS' Windows kernel-driver evolution
- Implement software supply-chain integrity controls (SBOM, package signing, update-server code signing) for vendor auto-update mechanisms after the FireAnt MetaKit and Mastra npm compromises
- Hunt for PNG/image steganographic payloads and COM-hijack persistence artifacts in environments exposed to Russian APT tooling
- Monitor for AES-encrypted WebSocket C2 and blockchain-resolved (e.g., Ethereum smart-contract) C2 address patterns associated with MaaS platforms like CastleRAT/ChainShell
CVEs associated with ASEC June 2026 APT Trend Report
Weaknesses (CWE) in ASEC June 2026 APT Trend Report
CWE-506, CWE-494, CWE-287
Timeline of ASEC June 2026 APT Trend Report
- APT28 (Fancy Bear) Operation Neusploit disclosed, exploiting CVE-2026-21509 in Microsoft Office to deliver the PixyNetLoader implant with PNG-steganography payload hiding and COM-hijacking persistence.
- Researchers at Ctrl-Alt-Intel discover an open directory listing on a C2 server, assessed with high confidence to belong to Iran's MuddyWater, containing the ChainShell PowerShell deployer (reset.ps1), Farsi code comments, and Israeli IP-range target lists.
- Public reporting links MuddyWater's use of the Russian-developed CastleRAT malware-as-a-service platform to the newly discovered ChainShell JavaScript/Node.js implant, which resolves its C2 address via an Ethereum smart contract over AES-encrypted WebSockets.
- MuddyWater observed abusing Microsoft Teams to steal credentials in a false-flag ransomware operation.
- North Korea's ScarCruft/APT37 deploys NarwhalRAT via spear-phishing messages impersonating Microsoft Account security notifications, staging data in a hidden %APPDATA%\naverwhale directory.
- ESET researchers document a previously undocumented Windows variant of the SprySOCKS backdoor, attributed to China-nexus FishMonger, featuring a kernel-driver rootkit and UEFI bootkit indicators.
- Google/Mandiant details Turla's (Secret Blizzard) new STOCKSTAY .NET/WebSocket backdoor, a KAZUAR-derived multi-component implant used against Ukrainian government/military and Italian-diplomacy-themed targets.
- ESET/OceanLotus (APT32) reporting reveals a supply-chain compromise of the FireAnt MetaKit stock-investment platform update server (active October 2025-March 2026), delivering the SPECTRALVIPER backdoor to a selective subset of Vietnamese stock investors.
- npm user 'sergey2016' publishes easy-day-js@1.11.21, a clean-looking typosquat of the dayjs library mimicking its metadata, used as bait for the subsequent Mastra compromise.
- Attacker compromises the @mastra npm organization and republishes 140+ packages (combined 1.1M+ weekly downloads) with easy-day-js added as a production dependency carrying an obfuscated postinstall dropper.
- Microsoft attributes the Mastra npm supply-chain campaign to North Korea's Sapphire Sleet group, citing infrastructure and post-compromise TTP overlap with prior Axios package compromise activity.
- AhnLab ASEC publishes its June 2026 APT trend digest synthesizing the above campaigns across 20 tracked nation-state groups spanning North Korea, China, Russia, Iran, and India/Southeast Asia.
Sources cited for ASEC June 2026 APT Trend Report
- APT Group Threat Report - June 2026
- From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
- 145 Mastra npm Packages Compromised via Hijacked Contributor Account
- Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat
- easy-day-js Supply Chain Attack Hits Mastra AI in npm
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
- FishMonger's arsenal upgraded: SprySOCKS for Windows
- China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
- Operation Neusploit: APT28 Weaponizes CVE-2026-21509
- APT28's Stealthy Multi-Stage Campaign Leveraging CVE-2026-21509 and Cloud C2 Infrastructure
- Operation Neusploit: APT28 Uses CVE-2026-21509
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
- The Latest Addition to Turla's Intelligence Gathering Apparatus
- Iranian Espionage Operations Linked To CastleRAT and ChainShell Malware Suite
Threats related to ASEC June 2026 APT Trend Report
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer Account
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign
- APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)
- ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP Staging with pCloud Dead-Drop C2
Detection coverage for TL-2026-1287
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1287 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.